Live data from Hacker News

Canonical Ltd source code repositories have been compromised

github.com

61–70 of 78 posts

Re: Canonical Ltd source code repositories have been compromised

#61
post #60

So... what’s the risk? If a person updated their Ubuntu computers this or last week, are they in trouble?

Hijacking top comment... We can confirm that on 2019-07-06 there was a Canonical owned account on GitHub whose credentials were compromised and used to create repositories and issues among other activities. Canonical has removed the compromised account from the Canonical organisation in GitHub and is still investigating the extent of the breach, but there is no indication at this point that any source code or PII was…

Thank for the update, David. Would this be an affected store? https://us.images.linuxcontainers.org/images/ubuntu/bionic/a...

Re: Canonical Ltd source code repositories have been compromised

#62
post #60

So... what’s the risk? If a person updated their Ubuntu computers this or last week, are they in trouble?

Hijacking top comment... We can confirm that on 2019-07-06 there was a Canonical owned account on GitHub whose credentials were compromised and used to create repositories and issues among other activities. Canonical has removed the compromised account from the Canonical organisation in GitHub and is still investigating the extent of the breach, but there is no indication at this point that any source code or PII was…

At least it wasn't as juvenile as the (possible actual) juvenile "hack"[0] of Gentoo's repos that had insertions of "rm -rf /" at the wrong places (where they wouldn't even execute) and insertions of racial slurs into readmes.

[0] https://wiki.gentoo.org/wiki/Project:Infrastructure/Incident...

Re: Canonical Ltd source code repositories have been compromised

#63
post #61
post #60

Earlier quoted context omitted.

Hijacking top comment... We can confirm that on 2019-07-06 there was a Canonical owned account on GitHub whose credentials were compromised and used to create repositories and issues among other activities. Canonical has removed the compromised account from the Canonical organisation in GitHub and is still investigating the extent of the breach, but there is no indication at this point that any source code or PII was…

Thank for the update, David. Would this be an affected store? https://us.images.linuxcontainers.org/images/ubuntu/bionic/a...

From our investigation so far, they do not appear to be, No.

Re: Canonical Ltd source code repositories have been compromised

#64

Earlier quoted context omitted.

Removed or made private (I see a 404 error only)

Somebody on twitter took some screenshot https://twitter.com/dclauzel/status/1147525512794988544

Actual link to screenshot: https://pbs.twimg.com/media/D-zUQ21XoAQeCgj.jpg

Re: Canonical Ltd source code repositories have been compromised

#66

So... what’s the risk? If a person updated their Ubuntu computers this or last week, are they in trouble?

Ironically I only use Ubuntu in a sandboxed environment, fresh install every time. I run apt get update and dont do any personal info stuff on it. This is out of sheer laziness because a USB stick is easier to plug in than Sata. Today I learned it is now has security features as well :) Canonical is a great thing in my life. Hope they haven't been hit too hard and that they learn how to prevent it.

I do not see how this will make you safer than running the distro from a disk drive. I believe you are at a higher risk than others because you are running apt update on every boot and thats how you would get infected if launchpad was compromised - but it is not.

Re: Canonical Ltd source code repositories have been compromised

#68
post #60

So... what’s the risk? If a person updated their Ubuntu computers this or last week, are they in trouble?

Hijacking top comment... We can confirm that on 2019-07-06 there was a Canonical owned account on GitHub whose credentials were compromised and used to create repositories and issues among other activities. Canonical has removed the compromised account from the Canonical organisation in GitHub and is still investigating the extent of the breach, but there is no indication at this point that any source code or PII was…

Launchpad doesn't look very trustworthy either: https://launchpad.net/projects/+all
Post reply on HN